Active incident or hacked WordPress? Ransomware Hacked WordPress 423-888-0252 · 828-484-1257

Panic triage · first day

First 24 hours after a WordPress hack: what to save and what not to click

You noticed something wrong: weird Google titles, a redirect, an unknown admin, a Chrome “this site may be hacked” warning, or spam you did not write. The urge is to delete everything or restore last week’s backup and hope. That can wipe the trail of how they got in and leave the door open.

Avery Parker · principal Support since the early 1990s Networks & security since the late 1990s Linux since ~2000 Johnson City office · you talk to the same person

This post is for the first day. It is not a full malware-removal guide. It is a calm order of operations so you do not make the mess worse, plus a clear line for when DIY should stop.

What “hacked” often looks like (pick what matches)

  • Search results show casino, loan, or pill titles while the logged-in homepage looks normal
  • Phones or logged-out visitors redirect; desktop admins see a normal site
  • An Administrator or Author account nobody created
  • Chrome or Search Console says the site may be compromised
  • Spam posts, fake pages, or links keep coming back after you delete them

If your store is taking bad payments, visitors are being harmed right now, or you are locked out of admin and host, skip the long DIY path and get incident-response help.

Hour 0 to 1: preserve, do not “fix”

  1. Do not wipe the host or restore blindly over the live site. You may destroy the only copy of the injected code and still leave a backdoor.
  2. Capture what you see (screenshots of SERP titles, redirects, the unknown user list, Search Console messages). Note the time.
  3. Take an off-server backup of files and the database if you still can (download a full backup to your computer or another host). Label it “pre-cleanup evidence.”
  4. Avoid clicking unknown “cleanup” plugins or random forum “paste this in functions.php” recipes. Many make forensics harder.
  5. Restrict access only if you know how (maintenance mode, IP allowlist, or temporary disable of public checkout) without deleting content you have not copied.

Hours 1 to 24: use a real first-day checklist

Work through our free WordPress compromise checklist (first 24 hours). It covers evidence, access hygiene, and stop-lines. The PDF does not fully clean a compromised site by itself. It helps you decide what is safe to touch and when to escalate.

Related symptom guides (if you already know the pattern):

When DIY should stop (call / book)

Stop scrubbing alone and use WordPress incident response when any of these are true:

  • Spam or redirects return after you delete them (likely persistence / backdoor)
  • You cannot trust remaining administrator accounts
  • Safe Browsing or Search Console flags remain after your deletes
  • WooCommerce or lead forms must stay up while cleanup is careful, not a wipe
  • You are out of time and need a written cleanup report, not more trial and error

Published cleanup packages start around $2,500 (typical ranges and combined cleanup + harden options are on the IR page). Work is remote nationwide; Tri-Cities / Western NC onsite is by appointment.

What careful cleanup usually means (expectations)

  • Preserve evidence, then remove planted content and persistence mechanisms
  • Avoid “one-click host clean” as the whole plan
  • Deliver a written report of what was found and changed
  • Search Console / Safe Browsing review is an owner step after pages are actually clean; we do not promise Google timelines

After cleanup, hardening and ongoing Care ($149 / $249 / $399) are optional sequels so the same door is less likely to reopen. They are not a substitute for Phase A cleanup when the site is still on fire. Care details: WordPress maintenance.

Soft start vs active fire

Free: first-24-hours checklist

Download the printable compromise checklist. Evidence, access hygiene, and stop-lines. Not a full clean by itself.

Get the free checklist

First-day questions

Should I restore last night’s backup right now?

Not until you have an off-server copy of the live (compromised) site labeled as evidence. A blind restore often puts the injector back and destroys the only forensic copy.

Is the free checklist a full malware cleanup?

No. It is a first-24-hours triage sheet: evidence, access hygiene, and stop-lines. Published cleanup packages with a written report live on the WordPress incident-response page.

When should I stop DIY and call?

When spam or redirects return after deletes, you cannot trust remaining admins, Safe Browsing or Search Console flags remain, the store must stay carefully up, or you need a written report instead of more trial and error.

Need the site cleaned without making it worse?

Tri-Cities 423-888-0252 · Western NC 828-484-1257